The personal data a carrier forgets it holds
By navichain team

Most transport operators meet data protection twice: when a customer’s procurement questionnaire arrives, and when somebody forwards an email about cookie banners. Both feel like paperwork about the website, which is the least of it.
The operation holds more personal data before lunch than the marketing site does in a year. Driver names, licence and CPC expiry dates, driver card downloads, positions logged every few minutes for a whole shift, a photograph of a pallet in a doorway, the name and phone number of whoever signed for it, a dashcam clip somebody kept in case it mattered later. None of it was collected in order to be data; it was collected because the day needed it.
What follows describes what the General Data Protection Regulation ((EU) 2016/679) says, with article numbers so you can read the text yourself. A description, not legal advice.
Write the list down, because the regulation asks for it
Article 30 requires a controller to keep a record of processing activities: the purposes, the categories of data subjects and of personal data, who receives it, and — where possible — erasure time limits and the security measures.
There is an exemption most small carriers assume covers them. Article 30(5) disapplies the obligation for an organisation employing fewer than 250 persons — unless the processing is likely to result in a risk to rights and freedoms, or the processing is not occasional, or it includes special categories of data. Dispatching, tracking, payroll and tachograph downloads are the opposite of occasional, so the threshold rescues very few operating businesses. That is less onerous than it sounds: the record is a table, and writing it is the only way to answer what follows without guessing.
Why you hold it is not a formality
Every processing operation needs a lawful basis under Article 6, and a carrier runs three at once.
Legal obligation, 6(1)(c). You keep tachograph records because the law says so. Regulation (EU) 165/2014, Article 33(2), requires transport undertakings to keep record sheets and printouts in legible form for at least a year after use, and to give copies to drivers who ask. The download intervals are fixed too: Regulation (EU) 581/2010 sets a maximum of 90 days for data from the vehicle unit and 28 days for data from the driver card, counting only days with recorded activity.
Contract, 6(1)(b). The consignee’s name and the address you deliver to exist because there is a job.
Legitimate interests, 6(1)(f). This is where vehicle tracking usually sits, and the article carries its own limit in the same sentence: those interests are a lawful basis “except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject”. A balance you are expected to have struck, not a box.
The trap is Article 5(1)(b), purpose limitation: data collected for specified, explicit and legitimate purposes must not be further processed in a manner incompatible with those purposes. Positions collected to plan the day and warn a receiver about a delay are one purpose. The same positions used six weeks later to argue with a driver about a lunch break are arguably another, and nobody wrote either down at the start.
The driver is an employee, which makes it harder
Employee data is the sharp end, because the person has limited practical freedom to refuse. Article 88 lets member states set more specific employment rules by law or by collective agreement, expressly including workplace monitoring systems — so “may we track our drivers this way?” is partly national, partly negotiated, and not readable off the regulation alone.
Two categories deserve care. Medical certificates and fitness-to-drive records are data concerning health, which Article 9(1) prohibits processing unless an exception applies — commonly 9(2)(b), employment-law obligations authorised by Union or member state law or by a collective agreement, with safeguards. And a fingerprint terminal or a face-recognising camera produces biometric data — data from specific technical processing that allows or confirms the unique identification of a person, per Article 4(14) — which 9(1) likewise prohibits processing for that purpose absent an exception. A fatigue camera that notices a closing eyelid and identifies nobody is a different thing entirely.
Cameras rarely get that care: a dashcam is bought as equipment, not as a processing operation. Article 35(1) requires a data protection impact assessment before processing likely to result in a high risk to rights and freedoms, and 35(3)(c) names systematic monitoring of a publicly accessible area on a large scale as a case that in particular requires one. Whether a given fleet’s forward-facing cameras meet that description is a judgement about scale and purpose; that the question applies is not. The ordinary questions follow — what is recorded, who watches it, on what trigger, how long it survives — and the EDPB’s guidelines on connected vehicles (version 2.0, adopted 9 March 2021) are the readable reference for them.
The people who never dealt with you at all
Your customer gave you a consignee’s name, address and mobile number. That person never spoke to you and may not know your company exists until a driver arrives.
Article 14 covers exactly this — information to be provided where personal data have not been obtained from the data subject — with a deadline: at the latest one month, or the first communication with that person, or the first disclosure to another recipient, whichever comes first. A notification SMS to a consignee is that first communication, so a link in it to your privacy notice is the cheapest way to meet the article. The exemptions in 14(5) are narrower than they look: the person already has the information, or providing it is impossible or a disproportionate effort — a phrase the regulation anchors to archiving, research and statistical purposes. “It would be awkward” is not on the list.
A signature captured at delivery is the same problem in miniature: personal data about a named individual, kept for years and reproduced on a proof of delivery you email onwards. That is a disclosure to a recipient, which Article 30(1)(d) expects you to be able to describe.
When someone asks
Requests are rare here, and expensive when unplanned. Article 15 gives a person the right to confirmation, access and a copy of the personal data being processed, plus the purposes, the recipients, the envisaged retention period and the source. Article 12(3) gives you one month to answer, extendable by two where the request is complex; 12(5) makes it free unless the request is manifestly unfounded or excessive.
The request to expect is a former driver asking for their positions, their tachograph data and whatever the telematics scored them on. Erasure has a limit worth knowing before you promise anything: Article 17(3)(b) disapplies the right where processing is necessary for compliance with a legal obligation. You do not delete tachograph records on demand. You do delete the things kept only because deleting them was never anybody’s job.
Retention is the part that is actually work
Article 5(1)(c) asks for data adequate, relevant and limited to what is necessary; 5(1)(e) says it must be kept in identifiable form no longer than is necessary; and 5(2) makes the controller responsible for demonstrating both. Together they turn retention from an opinion into a number decided in advance and evidenced afterwards.
Deciding the numbers is a morning’s work; enforcing them is the harder half, because a rule that depends on somebody remembering to delete is a description of an intention. What does the deleting matters more than what states the period — and where part of the answer to “who else can see this” is a supplier, what “EU-hosted” actually means covers that half.
Where navichain fits
navichain treats driver consent, retention periods and deletion eligibility as platform functions rather than paragraphs in a document — listed on the platform page beside the driving-time and vehicle rules, because in an operation they are the same kind of obligation. Access inside a tenant runs on roles and claim-based permissions per user and per department, with two-factor authentication for administrators and a field-level audit trail on the records that matter, and each customer’s data sits in an isolated per-tenant database within the EU. Our privacy policy is public. None of that decides the questions above for you, but it is what makes your answers enforceable.